Search

How can we help?

Icon

“Systematic Failings” on Data Protection leads to a £15,000 fine

Following on from the case reported last month on data protection (”Failing to anonymise – the cost”), a nursing home in Northern Ireland has received a fine of £15,000 from the Information Commissioner’s Office (“ICO”), following the burglary of the home of one of its staff members.

During the burglary, an unencrypted work laptop was stolen. The laptop contained sensitive personal data, including medical information, on the nursing home’s 29 residents (including “do not resuscitate” orders) and personal data on the 46 members of staff.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices. Data security training was also found to be lacking. In issuing the fine, the ICO said there had been “systematic failings” at the nursing home.

The fine was issued despite the nursing home referring themselves to the ICO, no complaints being made by any of the staff or residents’ families and no confirmation that the information had been further disseminated. In determining the level of the fine, the nursing home received some credit for having self-reported its breach to the ICO.

The ICO’s subsequent investigation found the nursing home had no policies in place regarding the use of encryption, working from home and the storage of mobile devices.

The amount of the fine reflected the size of the business, with the ICO stating that a bigger organisation experiencing a similarly serious breach should expect to receive a much larger fine. The case therefore acts as a timely reminder that all businesses must take their legal duties to look after personal data seriously and should ensure adequate policies, procedures and equipment are in place.  Simply having a work laptop password protected will not fulfil this duty.

For useful data protection factsheets, checklists and templates, please visit employmentbuddy.com 

For further advice on how to protect your business against data protection and privacy claims, please contact our employment lawyers on employment@clarkslegal.com 

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 24 June 2026
  • Employment

What are employer’s obligations during a heatwave?

During the summer, employers can come across employee issues relating to the heat and hot weather. How can employers handle hot weather and what are employer obligations during a heatwave?

art
  • 23 June 2026
  • Employment

Pride month and employment law: Ensuring compliance with LGBTQ+ protections

With each Pride month, companies unveil rainbow logos and send office wide emails of solidarity. These gestures are valuable, giving visible demonstrations of support, but only really make a difference if those companies are able to truly say that their policies and practices are inclusive and legally compliant.

art
  • 22 June 2026
  • Commercial Real Estate

Do you need an EPC for lease renewals? Key insights for commercial property owners

When is an EPC required for leases? The non-domestic EPC guidance makes it clear that an EPC is not required on renewal. The Ministry for Housing, Communities and Local Government’s (MHCLG’s) “A guide to energy performance certificates for the construction, sale and let of non-dwellings: Improving the energy efficiency of our buildings”

Pub
  • 18 June 2026
  • Employment

Employment Rights Act 2025: Key Changes for Employers

Join Katie Glendinning and Lucy White for an on demand webinar as they break down the key changes introduced by the Employment Rights Act 2025, offering clear insights into what these reforms mean in practice for employers and HR professionals.

art
  • 18 June 2026
  • Corporate and M&A

Business sales and NDAs: Creating a safe space to open up your business

You have accepted an offer to sell your business, but taking an agreement in principle through to completion may involve the need to divulge your company’s private information – perhaps deep secrets which have given your business its competitive edge.  

art
  • 16 June 2026
  • Employment

Shaping the Future of Work: Insights from the 114th ILO International Labour Conference

Having recently returned from the 114th Session of the International Labour Conference in Geneva, I have been reflecting on the work of the International Labour Organisation (ILO) and the important role it plays in global standard setting, as well as promoting social and economic inclusivity.